Frameworks / OWASP DevSecOps Maturity Model (DSOMM) / DSOMM-3 OWASP DevSecOps Maturity Model (DSOMM)
Build and Deployment
OWASP DevSecOps Maturity Model (DSOMM) DSOMM-3: Build, Deployment, Infrastructure Hardening, and Secrets Management Per OWASP DSOMM Build and Deployment + Infrastructure Hardening dimensions: secure the build + deployment + infrastructure stack. Requirements include (a) implement signed builds + artefact integrity + secure pipeline configuration + (b) operate vulnerability gating policies + environment promotion controls + (c) scan infrastructure-as-code + configuration-as-code + container images + (d) implement container + orchestration security including image scanning + runtime protection + admission control + (e) operate cloud security posture management + environment isolation + access controls + (f) implement secrets management including dedicated secret store + rotation + no hard-coded secrets + (g) implement configuration hardening baselines + drift detection + remediation.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 268 controls across 115 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-23 Baseline configuration establishment BSI-24 Configuration change control BSI-26 System component inventory BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management API1164-14 Physical Security API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures ASD37-04 User application hardening (Essential) ASD37-10 Server application hardening (Very Good) ASD37-11 Operating system hardening (Very Good) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls AWWA-4.3 Configuration Management AWWA-4.4 Audit Logging and Monitoring CAT-D3-1 Preventative controls CAT-D3-2 Detective controls CAT-D3-3 Corrective controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement GhCSA-Scope-CSAGhana-Defs Scope, Cyber Security Authority (CSA Ghana) and Key Definitions IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability IEEE1686-SupplyChain-Documentation-Procurement-ComplianceTable-Physical IEEE 1686 Section 6 IED Security Documentation + Supply Chain + Procurement Specification + Appendix A Compliance Table + Physical and Tamper 27011-5.3 Segregation of duties 27011-5.6 Supplier relationships and telecom supply chain 27011-8.1 User Endpoint Devices 27011-8.4 Logging and monitoring MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management MDS2-Physical-Security-PLOK-Workstation-Disposal-Backup-DTBK-Disaster-Recovery MDS2 Physical Security + PLOK + Workstation + Disposal + Backup + DTBK + Disaster Recovery MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) DIQ-1 Data Integration and Interoperability DSO-2 Data Security DSO-3 Data Access Management CJIS-16 Cloud Computing CJIS-19 Supply Chain Risk Management CJIS-7 Configuration Management FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests FedRAMP-SupplyChain-SBOM FedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF) 27010-15.1 Incident Management 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework NISTSP146-4 IaaS Operational Recommendations and Workload Hardening NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing AS9100D-8.1 Operational Planning and Control AS9100D-8.4 Control of Externally Provided Processes, Products, Services AEO-2 Demonstrated Compliance with Customs Requirements AEO-4 Financial Viability CA-ITSG33-SC-01 Security Control Catalogue CA-ITSG33-SC-03 Cloud Security Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e)) GAMP5-2nd-Edition-AI-Cloud-Agile-CSA 2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA) GAMP5-Supplier-Operations-Change-Periodic Supplier Assessment, Operational Phase, Change Control and Periodic Review HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain 62351-14 Cyber security event logging 62351-8 Role-based access control (RBAC) 27400-6.1 Secure Device Design 27400-6.4 Default Configuration Security ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL NAIC-2 Information Security Program (ISP) - Section 4 NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTSP115-2 Review Techniques - Documentation, Logs, Rulesets, Configurations NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup NISTSP137-4 Security Status Reporting and Risk Score Aggregation NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-5 Network, Endpoint, System Development, and Configuration Security OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records APPI-A26 Report of Leakage to the Commission and Notification to the Person ACQ.4 Supplier Monitoring LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A) GHG-Suite-Corporate-Principles GHG Protocol Suite, Corporate Standard and 5 Reporting Principles GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe A.1 Point-of-Care Testing Additional Requirements INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NHPA-7 Data Protection Assessments and Processor Contracts NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NZISM-3 Personnel Security, Physical Security, and Cryptography NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security OECDMNE-5 Environment, Climate, and Biodiversity OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices AUPRV-4 APP 10-11 Quality, Security of Personal Information PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability VERMONTAICDA-4 Vermont AG Enforcement and Cure Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 268 it maps to, and the evidence behind each claim, over MCP and REST.